# How best to flag security related issues?

**URL:** https://meta.discourse.org/t/how-best-to-flag-security-related-issues/45762
**Category:** Site feedback
**Created:** [16. Juni 2016 um 14:50 UTC](https://meta.discourse.org/t/how-best-to-flag-security-related-issues/45762 "2016-06-16T14:50:53Z")
**Posts on this page:** 5
**Page:** 1

<div class="post-metadata">

### Author: ![watchmanmonitor](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/watchmanmonitor/32/430970_2.png) [@watchmanmonitor](https://meta.discourse.org/u/watchmanmonitor)
#### Post date: [16. Juni 2016 um 14:50 UTC](https://meta.discourse.org/t/how-best-to-flag-security-related-issues/45762/1 "2016-06-16T14:50:53Z")

</div>

In my post here

> [@Pending members are emailed about posts](https://meta.discourse.org/t/pending-members-are-emailed-about-posts/39832/):
>
> As of v1.5.0.beta10 +105 users who have applied for an account, but are still pending review are getting emailed about user posts. The users show as Approved? No Active? No but still have ‘user posted’ emails in the logs.

Private data is being emailed to non-approved members. What’s the best way to flag security related issues on Meta?

---

<div class="post-metadata">

### Author: ![eviltrout](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/eviltrout/32/5275_2.png) [@eviltrout](https://meta.discourse.org/u/eviltrout)
#### Post date: [16. Juni 2016 um 15:22 UTC](https://meta.discourse.org/t/how-best-to-flag-security-related-issues/45762/2 "2016-06-16T15:22:44Z")

</div>

I’m not sure how that fell through the cracks but this is a good way to get my attention. I will be looking at it ASAP.

---

<div class="post-metadata">

### Author: ![watchmanmonitor](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/watchmanmonitor/32/430970_2.png) [@watchmanmonitor](https://meta.discourse.org/u/watchmanmonitor)
#### Post date: [16. Juni 2016 um 16:46 UTC](https://meta.discourse.org/t/how-best-to-flag-security-related-issues/45762/3 "2016-06-16T16:46:05Z")

</div>

Cool. Is there any utility in having a `security` tag on meta?

---

<div class="post-metadata">

### Author: ![eviltrout](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/eviltrout/32/5275_2.png) [@eviltrout](https://meta.discourse.org/u/eviltrout)
#### Post date: [16. Juni 2016 um 17:11 UTC](https://meta.discourse.org/t/how-best-to-flag-security-related-issues/45762/4 "2016-06-16T17:11:34Z")

</div>

I’m not sure that would have made me notice it faster unfortunately ☹

---

<div class="post-metadata">

### Author: ![codinghorror](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/codinghorror/32/110067_2.png) [@codinghorror](https://meta.discourse.org/u/codinghorror)
#### Post date: [16. Juni 2016 um 21:56 UTC](https://meta.discourse.org/t/how-best-to-flag-security-related-issues/45762/5 "2016-06-16T21:56:03Z")

</div>

The best way is to email `team@discourse.org` directly – this is covered in [discourse/docs/SECURITY.md at main · discourse/discourse · GitHub](https://github.com/discourse/discourse/blob/master/docs/SECURITY.md)
